Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.884216
Categoría:CentOS Local Security Checks
Título:CentOS: Security Advisory for gzip (CESA-2022:2191)
Resumen:The remote host is missing an update for the 'gzip'; package(s) announced via the CESA-2022:2191 advisory.
Descripción:Summary:
The remote host is missing an update for the 'gzip'
package(s) announced via the CESA-2022:2191 advisory.

Vulnerability Insight:
The gzip packages contain the gzip (GNU zip) data compression utility. gzip
is used to compress regular files. It replaces them with files containing
the .gz extension, while retaining ownership modes, access, and
modification times.

Security Fix(es):

* gzip: arbitrary-file-write vulnerability (CVE-2022-1271)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

Affected Software/OS:
'gzip' package(s) on CentOS 7.

Solution:
Please install the updated package(s).

CVSS Score:
9.0

CVSS Vector:
AV:N/AC:L/Au:S/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2022-1271
https://security.gentoo.org/glsa/202209-01
https://access.redhat.com/security/cve/CVE-2022-1271
https://bugzilla.redhat.com/show_bug.cgi?id=2073310
https://git.tukaani.org/?p=xz.git;a=commit;h=69d1b3fc29677af8ade8dc15dba83f0589cb63d6
https://lists.gnu.org/r/bug-gzip/2022-04/msg00011.html
https://security-tracker.debian.org/tracker/CVE-2022-1271
https://tukaani.org/xz/xzgrep-ZDI-CAN-16587.patch
https://www.openwall.com/lists/oss-security/2022/04/07/8
CopyrightCopyright (C) 2022 Greenbone Networks GmbH

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.